STIGQter STIGQter: STIG Summary: Red Hat Enterprise Linux 10 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

RHEL 10 must require users to provide a password for privilege escalation.

DISA Rule

SV-281211r1166585_rule

Vulnerability Number

V-281211

Group Title

SRG-OS-000373-GPOS-00156

Rule Version

RHEL-10-600560

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure RHEL 10 to not allow users to execute privileged actions without authenticating with a password.

Remove any occurrence of "NOPASSWD" found in the "/etc/sudoers" file or files in the "/etc/sudoers.d" directory:

$ sudo find /etc/sudoers /etc/sudoers.d -type f -exec sed -i '/NOPASSWD/ s/^/# /g' {} \;

Check Contents

Verify RHEL 10 has no occurrences of "NOPASSWD" in "/etc/sudoers" with the following command:

$ sudo grep -ir nopasswd /etc/sudoers /etc/sudoers.d/ | grep -v '#'

If any occurrences of "NOPASSWD" are returned from the command and have not been documented with the information system security officer as an organizationally defined administrative group using multifactor authentication, this is a finding.

Vulnerability Number

V-281211

Documentable

False

Rule Version

RHEL-10-600560

Severity Override Guidance

Verify RHEL 10 has no occurrences of "NOPASSWD" in "/etc/sudoers" with the following command:

$ sudo grep -ir nopasswd /etc/sudoers /etc/sudoers.d/ | grep -v '#'

If any occurrences of "NOPASSWD" are returned from the command and have not been documented with the information system security officer as an organizationally defined administrative group using multifactor authentication, this is a finding.

Check Content Reference

M

Target Key

5733